Desktop Operating Systems

I would avoid using Windows or macOS since both Operating Systems are proprietary and phone home to Microsoft/Apple. There are things you can do to improve privacy and security:

  • Encrypting your drive (Windows has a tool called BitLocker, Mac has a tool called FileVault)… I would avoid backing up the file to your Microsoft Account, OneDrive, or iCloud.
  • Avoiding a Microsoft/Apple Account (Microsoft unfortunately makes this harder than it should be)

…but in general, I would avoid them.

My general rule is to use some form of Linux or BSD. If you’re a new Linux user, I’d suggest Linux Mint (not because it’s the most private, but because it’s a good distro overall). If you’re a more seasoned Linux user, I hold the view that “less is more” and I’d suggest a minimal distro you configure yourself so you have a better understanding of what you’re running. Examples include Arch/Artix/Parabola, Debian/Devuan, Void, Gentoo, GNU Guix, and Alpine Linux.

On the BSD side, OpenBSD is technically the most secure, but FreeBSD and GhostBSD (which is based on FreeBSD) are far more practical as daily drivers.

(Note: Tails and QubesOS are often cited as the most private/secure Linux distros, but they also serve very specific purposes which limit their suitability as a daily driver).

Mobile Operating Systems

TLDR - use a degoogled Android ROM (e.g., LineageOS, /e/OS, GrapheneOS, Calyx) or use a Linux-based mobile OS (e.g., Ubuntu Touch, postmarketOS). I would avoid using stock Android or iOS.

(Note: GrapheneOS currently only supports Google Pixel hardware. If that is a dealbreaker, use one of the other custom Android ROMs).

Web Browsers

The issue here is “privacy-respecting browser” could mean anything from “we don’t personally collect your data” (e.g., Chromium) to “we actively block stuff that can be used to track you” (e.g., GNU Icecat, Tor Browser, LibreWolf).

The browsers that actually protect your privacy may have limitations unless you enable certain features (e.g., third-party cookies, WebGL, fingerprinting, DRM-protected content). For example, Icecat comes with an extension called LibreJS, which blocks non-free JavaScript, which a lot of websites depend on.

I would avoid proprietary web browsers (e.g., Microsoft Edge, Google Chrome, Opera, Safari). FOSS browsers are the way to go, but you may have to tweak them to get the right balance of privacy and functionality. Note that a browser can be free software and still have privacy issues (e.g., Firefox).

Instant Messengers

I would use something that meets the following criteria:

  • Free Software
    • This eliminates most mainstream options like Discord and WhatsApp.
  • Preferably decentralised
    • The way decentralisation works varies… some are fully peer-to-peer (e.g., Jami), others involve setting up independent servers/instances (e.g., Matrix, XMPP).
  • Doesn’t require personally identifiable information to register
  • Supports end-to end encryption
    • Preferably, you should be able to manage E2EE yourself

There are actually a lot of messengers/protocols which meet this criteria (Jami, Session, SimpleX, Briar, Matrix, XMPP), but the bigger limitation is the social effect. A messenger may respect your privacy, but it’s functionally useless if you have nobody to talk to.

Email

For the best privacy, you should self-host your own mail server, but this isn’t practical for many people and it has some downsides (e.g., large providers like Gmail will probably flag you as spam).

I would avoid mainstream mail providers (e.g., Gmail, Outlook, iCloud, Yahoo, Aol). Smaller providers like Proton Mail, Tuta Mail, Fastmail, and mailbox.org are generally better (provided you don’t rely on one company for everything), but they’re not perfect, they can be hacked, and they can be forced to hand over data at the request of law enforcement.

Some providers like Proton Mail and Tuta Mail support E2EE, but by default messages will only be end-to-end encrypted if you’re contacting another Proton/Tuta user.

For optimal confidentiality: you and your contacts should generate your own keypairs, share your public keys (keep your private keys to yourself!), and encrypt/sign/decrypt your stuff manually.

VPN

Ideally, you would host your own VPN on a remote VPS since it’s a lot harder for your own servers to be blocked, but setting up a VPS for a bunch of different countries is expensive.

For paid options, I’d suggest either Mullvad or IVPN. Neither is perfect, but they do not have the same level of KYC as the big names (e.g., NordVPN, ExpressVPN, Surfshark) since your account is just a randomly generated number/ID and payment can be done via crypto (including Bitcoin and Monero) or even physical cash (make sure you follow their instructions properly).

Proton VPN is decent as a free (gratis) option, but the free tier only includes a few countries (e.g., United States, Japan, Netherlands). I would not trust some random “free” VPN you see as a browser extension or in an app store.

Depending on your use case, you may not even need a VPN and the Tor Network may suffice (I’d suggest booting into Tails rather than installing the Tor Browser on your host machine).

Password Manager

I suggest using an offline password manager like Keepass, which has many clients for different platforms (e.g., KeepassXC on desktop, KeepassDX on Android).

I do not recommend online password managers. They may be convenient, but it carries its own risk if the provider is hacked or has a data breach, especially if the hash for your master password is leaked.